September 15, 2026A–D

Card Not Present Fraud

card not present fraud, CNP fraud, card not present transaction, card not present fraud prevention, CNP fraud detection, card present vs card not present, card not present fraud statistics
What separates card present from card not present arrow

Card not present fraud (CNP fraud) is the unauthorised use of stolen card credentials in a transaction where the physical card is never presented – online, in-app, over the phone, or by mail order. Because no chip is read and no PIN is entered at a terminal, the payment is authorised on data alone: card number, expiry date, CVV, and whatever contextual signals the merchant and issuer can assemble around them.

A card not present transaction is not suspicious by nature. It is the default shape of e-commerce, recurring billing, BNPL checkout and digital lending disbursement. CNP fraud is simply what happens when the credential is genuine and the person using it is not – and the payment rail has no physical proof either way.

What separates card present from card not present

In a card present transaction, the chip performs cryptographic authentication at the terminal. The card proves it is the card. Counterfeiting that is expensive, which is why EMV migration pushed organised fraud into remote channels rather than eliminating it.

In the card not present case, that proof disappears. The issuer is left inferring legitimacy from static data that leaks constantly through breaches, phishing and dark-web resale. Every authentication layer added since – AVS, CVV checks, 3-D Secure, one-time passcodes – is an attempt to rebuild the missing proof out of context rather than out of cryptography at the point of sale.

Where card not present fraud starts

The transaction is the last step, not the first. Stolen credential sets are usually validated before they are spent: card testing runs small, low-value attempts across merchants with light monitoring, confirming which numbers are live before the working ones are used or resold. By the time a loss appears, the card has often already been tested.

The second route is authentication itself. Social engineering aimed at extracting one-time passcodes lets a fraudster provision stolen card details into a digital wallet or clear a challenge directly. Once the passcode is handed over, the resulting payment reaches the issuer authenticated. Strong customer authentication has been satisfied. The transaction can look cleaner than a legitimate one placed from an unfamiliar browser, and by that point the decision is already lost.

Card not present fraud prevention that holds up

Credential checks remain necessary and are no longer sufficient on their own. CNP fraud prevention depends on evaluating the environment a transaction originates from, not only the data it carries:

  • Session and device context. Emulators, virtual machines, remote access tools, randomised browser configurations and rotating connections are all observable before authorisation. A device with no history that has just requested wallet provisioning behaves nothing like a returning customer.
  • Correlation across attempts. One new device is not fraud. Dozens of card attempts from one device configuration, or one card across dozens of devices, is a fraud ring. Card testing is only visible at the aggregate layer.
  • Velocity and behaviour, not just value. Typing cadence, copy-paste into sensitive fields, and navigation that is too linear for a human are all available at no friction cost to genuine users.
  • Authenticated does not mean legitimate. Any CNP fraud detection model that treats a passed 3-D Secure challenge as terminal will keep approving socially engineered transactions. Device and behavioural signals give risk teams a second, independent read. Device intelligence supports this layer without relying on direct user identifiers, which matters in markets governed by GDPR, LGPD, the DPDP Act and comparable regimes, and in portfolios where bureau coverage is uneven.

FAQ

What is a card not present transaction?

A card not present transaction is any payment completed without the physical card being read by a terminal – online checkouts, in-app purchases, phone orders and mail order. The merchant submits card data rather than a chip-authenticated cryptogram, so authorisation depends on data and context alone.

What is the difference between card present and card not present fraud?

Card present fraud requires physical possession of a card or a counterfeit copy and is limited by geography. Card not present fraud needs only the credential data, scales without physical constraints, and can be executed from anywhere against any remote merchant.

Is CVV enough to prevent card not present fraud?

No. CVV confirms the entered code matches issuer records, but breached and phished datasets routinely include it. CVV filters opportunistic attempts and does nothing against validated credential sets, which is why layered CNP fraud detection is standard practice.

How can card not present fraud be prevented?

By combining credential verification with session-level assessment: device and environment signals, behavioural anomalies, connection analysis and cross-attempt correlation. Prevention works best before authorisation, at login and wallet provisioning, rather than at the transaction alone.

Share this post

See How We Spot Fraud Before It Happens — Book Your Expert Session

  • list marker

    See It in Action with a Real Expert

    Get a live session with our specialist who will show how your business can detect fraud attempts in real time.

  • list marker

    Explore Real Device Insights in Action

    Learn how unique device fingerprints help you link returning users and separate real customers from fraudsters.

  • list marker

    Understand Common Fraud Scenarios

    Get insights into the main fraud tactics targeting your market — and see how to block them.

Our Contacts:

Leading Brands Trust JuicyScore:

robocash
id finance
tabby

Get in touch with us

Our dedicated experts will reach out to you promptly